<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39004#M2211</link>
    <description>Hi Mike,&lt;BR /&gt;
&lt;BR /&gt;
Case 2 displays the username but that username "00-11-22-AA-BB-CC" is not correct. It was just for testing purpose to see wheter or not NAC ignors MAC like usernames in general or only if they equal to the MAC address.&lt;BR /&gt;
&lt;BR /&gt;
The MAC address of the device is: 00-1A-E8-27-76-8A&lt;BR /&gt;
The username which should be in the certificate is: 00-1A-E8-27-76-8A&lt;BR /&gt;
&lt;BR /&gt;
But as you see NAC does not display the username if the CN equals the MAC.&lt;BR /&gt;
&lt;BR /&gt;
Alright I will open a case.&lt;BR /&gt;
&lt;BR /&gt;
Thanks a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Michael</description>
    <pubDate>Thu, 06 Aug 2015 19:12:00 GMT</pubDate>
    <dc:creator>Michael_Kirchne</dc:creator>
    <dc:date>2015-08-06T19:12:00Z</dc:date>
    <item>
      <title>NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39000#M2207</link>
      <description>Hi Community,&lt;BR /&gt;
&lt;BR /&gt;
I have a little issue withe NetSight / NAC 6.3 with EAP-TLS.&lt;BR /&gt;
&lt;BR /&gt;
If the CN in the client certificate equals the MAC address, then the username field is empty.&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ca24e4bf12f34b85824c86d33267d1fa_RackMultipart20150806-8471-13j970z-username_empty_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4863i3A0D42A47320792E/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca24e4bf12f34b85824c86d33267d1fa_RackMultipart20150806-8471-13j970z-username_empty_inline.png" alt="ca24e4bf12f34b85824c86d33267d1fa_RackMultipart20150806-8471-13j970z-username_empty_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Otherwise the the filed is filled:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ca24e4bf12f34b85824c86d33267d1fa_RackMultipart20150806-18413-1pz05kc-username_filled_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4605i0568A186ABE4BCC2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca24e4bf12f34b85824c86d33267d1fa_RackMultipart20150806-18413-1pz05kc-username_filled_inline.png" alt="ca24e4bf12f34b85824c86d33267d1fa_RackMultipart20150806-18413-1pz05kc-username_filled_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
RADIUS / Certificate Diagnostics (CN=MAC):&lt;BR /&gt;
User-Name = "00-1A-E8-27-76-8A"  Service-Type = Framed-User  Called-Station-Id = "20-B3-99-0B-6A-94"  Calling-Station-Id = "00-1A-E8-27-76-8A"  NAS-Identifier = "Demokit D2"  NAS-IP-Address = 192.168.10.10  NAS-Port = 8  NAS-Port-Id = "ge.1.8"  Framed-MTU = 1500  NAS-Port-Type = Ethernet  State = 0x7077081978e6055d5931c04285fc9f93  EAP-Message = 0x029100060d00  Message-Authenticator = 0xa8aaa0067409760bc450db9db1a2a7c4  ETS-Outer-Tunnel-Username = "00-1A-E8-27-76-8A"  ETS-NTLM-Auth-Allowed = 0  ETS-Cleartext-Password =  EAP-Type = EAP-TLS  TLS-Cert-Serial := "11ab00d3000700000039"  TLS-Cert-Expiration := "200801150226Z"  TLS-Cert-Subject := "/C=DE/DC=com/DC=demo/DC=unify/CN=Demokit Issuing CA"  TLS-Cert-Issuer := "/DC=com/DC=demo/DC=unify/CN=Unify Demo Root CA"  TLS-Cert-Common-Name := "Demokit Issuing CA"  TLS-Client-Cert-Serial := "610f05e900010000001f"  TLS-Client-Cert-Expiration := "170806112608Z"  TLS-Client-Cert-Subject := "/C=DE/ST=BW/L=Stuttgart/O=Unify Deutschland GmbH &amp;amp; Co. KG/OU=PSS UCC 3.2/CN=00-1A-E8-27-76-8A"  TLS-Client-Cert-Issuer := "/C=DE/DC=com/DC=demo/DC=unify/CN=Demokit Issuing CA"  TLS-Client-Cert-Common-Name := "00-1A-E8-27-76-8A"  TLS-Client-Cert-X509v3-Subject-Key-Identifier += "5A:60:B4:7E:F7:36:B7:22:F1:39:31:8C:B1:6B:61:BF:BE:85:BE:7D"  TLS-Client-Cert-X509v3-Authority-Key-Identifier += "keyid:07:F3:A1:4C:98:90:42:58:9A:FB:B2:67:A5:09:25:E1:76:16:77:06\n"  TLS-Client-Cert-X509v3-Extended-Key-Usage += "TLS Web Server Authentication, TLS Web Client Authentication"&lt;BR /&gt;
RADIUS / Certificate Diagnostics (CN!=MAC):&lt;BR /&gt;
User-Name = "00-11-22-AA-BB-CC"  Service-Type = Framed-User  Called-Station-Id = "20-B3-99-0B-6A-94"  Calling-Station-Id = "00-1A-E8-27-76-8A"  NAS-Identifier = "Demokit D2"  NAS-IP-Address = 192.168.10.10  NAS-Port = 8  NAS-Port-Id = "ge.1.8"  Framed-MTU = 1500  NAS-Port-Type = Ethernet  State = 0xda612f8ad24a226d68a952489ecc2114  EAP-Message = 0x022b00060d00  Message-Authenticator = 0xf9175123bf64dac6666667d70b4d4fae  ETS-Outer-Tunnel-Username = "00-11-22-AA-BB-CC"  ETS-NTLM-Auth-Allowed = 0  ETS-Cleartext-Password =  EAP-Type = EAP-TLS  TLS-Cert-Serial := "11ab00d3000700000039"  TLS-Cert-Expiration := "200801150226Z"  TLS-Cert-Subject := "/C=DE/DC=com/DC=demo/DC=unify/CN=Demokit Issuing CA"  TLS-Cert-Issuer := "/DC=com/DC=demo/DC=unify/CN=Unify Demo Root CA"  TLS-Cert-Common-Name := "Demokit Issuing CA"  TLS-Client-Cert-Serial := "6153011a000100000020"  TLS-Client-Cert-Expiration := "170806124023Z"  TLS-Client-Cert-Subject := "/C=DE/ST=BW/L=Stuttgart/O=Unify/OU=PSS UCC 3.2/CN=00-11-22-AA-BB-CC"  TLS-Client-Cert-Issuer := "/C=DE/DC=com/DC=demo/DC=unify/CN=Demokit Issuing CA"  TLS-Client-Cert-Common-Name := "00-11-22-AA-BB-CC"  TLS-Client-Cert-X509v3-Subject-Key-Identifier += "54:7C:C6:4A:3C:D5:F0:C0:F0:D3:14:40:67:33:79:E5:F6:AF:29:0D"  TLS-Client-Cert-X509v3-Authority-Key-Identifier += "keyid:07:F3:A1:4C:98:90:42:58:9A:FB:B2:67:A5:09:25:E1:76:16:77:06\n"  TLS-Client-Cert-X509v3-Extended-Key-Usage += "TLS Web Server Authentication, TLS Web Client Authentication"&lt;BR /&gt;
Hope anyone has an idea why the username is not extracted correctly.&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Michael</description>
      <pubDate>Thu, 06 Aug 2015 17:56:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39000#M2207</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-08-06T17:56:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39001#M2208</link>
      <description>Hi Michael,&lt;BR /&gt;
1. Is the behavior different than in 6.2.x.x?&lt;BR /&gt;
2. The radius output attribute user-name and TLS-client-Cert-Common name are mac's in both cases. Are you certain that the second one displayed the username, and the first did not?&lt;BR /&gt;
3. The conflicting info looks that the screenshot shows the host MAC-address as "76-7A" in both cases.</description>
      <pubDate>Thu, 06 Aug 2015 18:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39001#M2208</guid>
      <dc:creator>Mike_Thomas</dc:creator>
      <dc:date>2015-08-06T18:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39002#M2209</link>
      <description>Hi Mike,&lt;BR /&gt;
&lt;BR /&gt;
thanks for your reply.&lt;BR /&gt;
1. I can't tell you for sure - my LAB equipment is running NetSight 6.3.0.142 right now.&lt;BR /&gt;
2. Yes, first case was MAC=CN and with the second case I was trying a username which is a MAC but does not eual the MAC of the device.&lt;BR /&gt;
-&amp;gt; Yes I'm certin. I checked with serveral certificates issued by different CAs.&lt;BR /&gt;
3. Yes, both cases were the same device (phone). Just the certificates were different.&lt;BR /&gt;
&lt;BR /&gt;
Case 1:&lt;BR /&gt;
CN=MAC e.g. CN=00-1A-E8-27-76-8A or CN=001AE827768A or CN=00:1A:E8:27:76:8A&lt;BR /&gt;
&lt;BR /&gt;
Case 2:&lt;BR /&gt;
CN!=MAC e.g, CN=00-1A-E8-27-76-8A.demo.com or any other CN&lt;BR /&gt;
&lt;BR /&gt;
Hope that helped to clear things up.&lt;BR /&gt;
&lt;BR /&gt;
I came across that issue while I was testing our Phone Certificate Deployment in my lab.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
Michael</description>
      <pubDate>Thu, 06 Aug 2015 18:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39002#M2209</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-08-06T18:42:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39003#M2210</link>
      <description>Which case displays the username? Which is the mac of the device? Both show the mac as the same, but username is different in the pics. case 2 appears to work, correct?&lt;BR /&gt;
first&lt;BR /&gt;
User-Name = "00-1A-E8-27-76-8A"&lt;BR /&gt;
TLS-Client-Cert-Common-Name := "00-1A-E8-27-76-8A"&lt;BR /&gt;
second&lt;BR /&gt;
User-Name = "00-11-22-AA-BB-CC"&lt;BR /&gt;
TLS-Client-Cert-Common-Name := "00-11-22-AA-BB-CC"&lt;BR /&gt;
The source appears to be 76-8A in both cases, so it's confusing. We may need to open a case so you can send in those certificates I guess, traces and some debug which don't belong here, but maybe we are actually not looking at the right info.</description>
      <pubDate>Thu, 06 Aug 2015 19:06:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39003#M2210</guid>
      <dc:creator>Mike_Thomas</dc:creator>
      <dc:date>2015-08-06T19:06:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39004#M2211</link>
      <description>Hi Mike,&lt;BR /&gt;
&lt;BR /&gt;
Case 2 displays the username but that username "00-11-22-AA-BB-CC" is not correct. It was just for testing purpose to see wheter or not NAC ignors MAC like usernames in general or only if they equal to the MAC address.&lt;BR /&gt;
&lt;BR /&gt;
The MAC address of the device is: 00-1A-E8-27-76-8A&lt;BR /&gt;
The username which should be in the certificate is: 00-1A-E8-27-76-8A&lt;BR /&gt;
&lt;BR /&gt;
But as you see NAC does not display the username if the CN equals the MAC.&lt;BR /&gt;
&lt;BR /&gt;
Alright I will open a case.&lt;BR /&gt;
&lt;BR /&gt;
Thanks a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Michael</description>
      <pubDate>Thu, 06 Aug 2015 19:12:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39004#M2211</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-08-06T19:12:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39005#M2212</link>
      <description>My goal was to see whether I run into the same issue with EAP PEAP.&lt;BR /&gt;
Setup: 802.1X WLAN service, NAC 6.3, Win AD/LDAP, EWC 9.21.&lt;BR /&gt;
&lt;BR /&gt;
So instead of my normal username "dvorakr" I've done a copy of the user in AD and used the MAC as the username = "2477033BD329"&lt;BR /&gt;
&lt;BR /&gt;
In that case I can't connect to the WLAN.&lt;BR /&gt;
NAC client state is "reject" and the reason is that the authentication is MAC EAP-MD5 instead of 802.1X PEAP.&lt;BR /&gt;
&lt;BR /&gt;
I've tried it with Cisco Anyconnect and also the build in Win7 client and both are set to PEAP.&lt;BR /&gt;
&lt;BR /&gt;
So I've created another account on my AD with the MAC but changed the last digit to an 8 = not my WLAN MAC anymore and I'm able to connect.&lt;BR /&gt;
&lt;BR /&gt;
Looks like there is something going wrong if the username = MAC.&lt;BR /&gt;
&lt;BR /&gt;
I can't tell whether that is related to the WIN AD/LDAP or the controller or NAC.&lt;BR /&gt;
&lt;BR /&gt;
-Ron&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Aug 2015 22:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39005#M2212</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2015-08-06T22:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - EAP-TLS - Username is not diplayed if CN equals MAC</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39006#M2213</link>
      <description>Hi Ron,&lt;BR /&gt;
&lt;BR /&gt;
I also hat the issue with MAC EAP-MD5. I had to disable MAC EAP-MD5 in the Advanced AAA Config. After that I successfully authenticated via EAP-TLS.&lt;BR /&gt;
&lt;BR /&gt;
If you're not using MAC EAP-MD5 for MAC Authentication you could also disable it and give it a try.&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Michael</description>
      <pubDate>Fri, 07 Aug 2015 14:13:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-eap-tls-username-is-not-diplayed-if-cn-equals-mac/m-p/39006#M2213</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-08-07T14:13:00Z</dc:date>
    </item>
  </channel>
</rss>

